Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Fixed issues

Splunk Enterprise 7.2.6

Splunk Enterprise 7.2.6 was released on April 16, 2019. This release includes fixes for the following issues.

Issues are listed in all relevant sections. Some issues might appear more than once. To check for additional security issues related to this release, visit the Splunk Security Portal.

Data input issues

Date resolved Issue number Description
2019-03-29 SPL-167747, SPL-162492 Web UI is counting "Number of (monitored) files" inconsistently

Search issues

Date resolved Issue number Description
2019-04-03 SPL-168692, SPL-166401 sendemail send messages when search does not return any result resulting in empty messages
2019-03-29 SPL-167582, SPL-156535 TcpChannelThread crashed due to race condition when multiple threads updating a ExternalProcessToken object simultaneously
2019-03-18 SPL-167324, SPL-158669 scanCount matches eventCount w/transforming command

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2019-04-09 SPL-168759, SPL-136608 Users don't have capability "accelerate_search", can not access accelerated reports
2019-04-01 SPL-167634, SPL-167802 10k+ buckets in DMA summary time range causes dramatic increase in SH DMA job runtime
2019-04-01 SPL-168109, SPL-164733 tstats searches do not run on datamodels that contain only a streamable BaseSearch object
2019-03-26 SPL-159290, SPL-158578 DMA populating data only for the default distributed search group.
2019-03-25 SPL-167959, SPL-153839, SPL-168046, SPL-168113 Splunk crashes on startup after upgrade to 7.2.5 due to invalid FIELDALIAS definition

Data model and pivot issues

Date resolved Issue number Description
2019-04-09 SPL-168759, SPL-136608 Users don't have capability "accelerate_search", can not access accelerated reports
2019-04-01 SPL-167634, SPL-167802 10k+ buckets in DMA summary time range causes dramatic increase in SH DMA job runtime
2019-04-01 SPL-168109, SPL-164733 tstats searches do not run on datamodels that contain only a streamable BaseSearch object
2019-03-26 SPL-159290, SPL-158578 DMA populating data only for the default distributed search group.
2019-03-25 SPL-167959, SPL-153839, SPL-168046, SPL-168113 Splunk crashes on startup after upgrade to 7.2.5 due to invalid FIELDALIAS definition

Indexer and indexer clustering issues

Date resolved Issue number Description
2019-04-02 SPL-168072, SPL-168054 Peer flaps from Up to BatchAdding when handleBucketsNotificationBatch is rejected during Master un-initialized
2019-04-01 SPL-168508, SPL-163391 Multi-Site Clustering - Splunk Indexer Discovery Failover is Failing on UFs
2019-04-01 SPL-168126, SPL-166936 Indexer Cluster continually tries to roll hot bucket that has already been rolled.

Universal forwarder issues

Date resolved Issue number Description
2019-04-02 SPL-163851, SPL-166696 Bugcheck due to splunkdrv (WinRegMon driver)

Windows-specific issues

Date resolved Issue number Description
2019-04-07 SPL-165772, SPL-158510 Splunk Perfmon-Collected Events Not Coinciding with WinPerfmon Data

Authentication and Authorization issues

Date resolved Issue number Description
2019-03-29 SPL-167968, SPL-123301 Aggressive calls to LDAP for non-existent/inactive users causes slow logins, performance issues/ skipped searches/ indexing pause
2019-03-13 SPL-167535, SPL-166078 HTTP 404 when ToS not accepted and URL has query strings. (daf)

Uncategorized issues

Date resolved Issue number Description
2019-04-03 SPL-168026, SPL-167635 Failed to localize because of CacheManager inconsistent bucket state after a truncate
2019-03-29 SPL-164859, SPL-167178, SPL-167179 Error in 'summaryindex' command: You have insufficient privileges to run this command.
2019-03-27 SPL-167655, SPL-166228 Splunk crashes in _mongoc_openssl_ctx_new on shutdown
2019-03-25 SPL-166011, SPL-167057 Field Extractor (IFX) returns no regex 'rules' in http response
2019-03-18 SPL-167015, SPL-143275 Bucket rebuild fails with reason: Failed to process delete journals
PREVIOUS
Field alias behavior change
  NEXT
Deprecated features

This documentation applies to the following versions of Splunk® Enterprise: 7.2.6


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters